=========================================================================Ubuntu Security Notice USN-2438-1
December 10, 2014

nvidia-graphics-drivers-304, nvidia-graphics-drivers-304-updates,
nvidia-graphics-drivers-331, nvidia-graphics-drivers-331-updates vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in the NVIDIA graphics drivers.

Software Description:
- nvidia-graphics-drivers-304: NVIDIA binary Xorg driver
- nvidia-graphics-drivers-304-updates: NVIDIA binary Xorg driver
- nvidia-graphics-drivers-331: NVIDIA binary Xorg driver
- nvidia-graphics-drivers-331-updates: NVIDIA binary Xorg driver

Details:

It was discovered that the NVIDIA graphics drivers incorrectly handled GLX
indirect rendering support. An attacker able to connect to an X server,
either locally or remotely, could use these issues to cause the X server to
crash or execute arbitrary code resulting in possible privilege escalation.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.10:
  nvidia-304                      304.125-0ubuntu0.1
  nvidia-304-updates              304.125-0ubuntu0.1
  nvidia-331                      331.113-0ubuntu0.1
  nvidia-331-updates              331.113-0ubuntu0.1

Ubuntu 14.04 LTS:
  nvidia-304                      304.125-0ubuntu0.0.1
  nvidia-304-updates              304.125-0ubuntu0.0.1
  nvidia-331                      331.113-0ubuntu0.0.4
  nvidia-331-updates              331.113-0ubuntu0.0.4

Ubuntu 12.04 LTS:
  nvidia-304                      304.125-0ubuntu0.0.0.1
  nvidia-304-updates              304.125-0ubuntu0.0.0.1
  nvidia-331                      331.113-0ubuntu0.0.0.3
  nvidia-331-updates              331.113-0ubuntu0.0.0.3

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-2438-1
  CVE-2014-8091, CVE-2014-8098, CVE-2014-8298

Package Information:

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.125-0ubuntu0.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304-updates/304.125-0ubuntu0.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331/331.113-0ubuntu0.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331-updates/331.113-0ubuntu0.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.125-0ubuntu0.0.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304-updates/304.125-0ubuntu0.0.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331/331.113-0ubuntu0.0.4

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331-updates/331.113-0ubuntu0.0.4

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.125-0ubuntu0.0.0.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304-updates/304.125-0ubuntu0.0.0.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331/331.113-0ubuntu0.0.0.3

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331-updates/331.113-0ubuntu0.0.0.3


Ubuntu 2438-1: NVIDIA graphics drivers vulnerabilities

December 10, 2014
Several security issues were fixed in the NVIDIA graphics drivers.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 14.10: nvidia-304 304.125-0ubuntu0.1 nvidia-304-updates 304.125-0ubuntu0.1 nvidia-331 331.113-0ubuntu0.1 nvidia-331-updates 331.113-0ubuntu0.1 Ubuntu 14.04 LTS: nvidia-304 304.125-0ubuntu0.0.1 nvidia-304-updates 304.125-0ubuntu0.0.1 nvidia-331 331.113-0ubuntu0.0.4 nvidia-331-updates 331.113-0ubuntu0.0.4 Ubuntu 12.04 LTS: nvidia-304 304.125-0ubuntu0.0.0.1 nvidia-304-updates 304.125-0ubuntu0.0.0.1 nvidia-331 331.113-0ubuntu0.0.0.3 nvidia-331-updates 331.113-0ubuntu0.0.0.3 After a standard system update you need to reboot your computer to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2438-1

CVE-2014-8091, CVE-2014-8098, CVE-2014-8298

Severity
December 10, 2014

Package Information

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.125-0ubuntu0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304-updates/304.125-0ubuntu0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331/331.113-0ubuntu0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331-updates/331.113-0ubuntu0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.125-0ubuntu0.0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304-updates/304.125-0ubuntu0.0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331/331.113-0ubuntu0.0.4 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331-updates/331.113-0ubuntu0.0.4 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.125-0ubuntu0.0.0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304-updates/304.125-0ubuntu0.0.0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331/331.113-0ubuntu0.0.0.3 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331-updates/331.113-0ubuntu0.0.0.3

Related News